Privacy Policy
Version as of September 2026
This English text is provided for convenience. The German version, Datenschutzerklärung, is the authoritative legal text under German law.
Hi, glad you're here! I'm Julius Niehus, and I'm the person behind "Revelion Method", operating through my company Julius Niehus Consulting UG (haftungsbeschränkt) (referred to simply as "I" or "me" throughout this Privacy Policy). Protecting your data matters a lot to me, so I only process your personal data to the extent permitted by applicable law, in particular the EU General Data Protection Regulation ("GDPR") and the German Telecommunications-Digital-Services-Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, "TDDDG").
With this Privacy Policy, I inform you in accordance with Article 13 GDPR about how I process your personal data through my website revelionmethod.com and my career test "Your Next Career Step" at test.revelion.coach (together the "Website").
But first, let's quickly clear up what I actually mean by "personal data": it's simply any piece of information that says something about you and could be traced back to you – think your name, your email address, your IP address, or anything else that points to an identified or identifiable natural person. In short: if it can be linked to you, it counts.
By using my Website, you're on board with the terms of this Privacy Policy. Sticking around and continuing to use the Website means you accept it, along with any updates I make down the line.
I. General Information
1. Controller
Under Article 4 (7) GDPR, the person responsible for processing your personal data is me, acting through:
Julius Niehus Consulting UG (haftungsbeschränkt)
Flottwellstr. 26, 10785 Berlin, Germany
Phone: +49 (0) 17664132133
Email: julius@revelionmethod.com
Julius Niehus Consulting UG (haftungsbeschränkt) has its registered seat in Berlin, is registered with the local court of Berlin (Charlottenburg) under HRB 256058 B, and I represent it as managing director, Julius August Niehus.
Revelion Method is simply the brand and trading name I go by, operating through Julius Niehus Consulting UG (haftungsbeschränkt), which remains the sole controller responsible for the data processing described in this Privacy Policy.
2. Data Protection Officer
I am not legally required to appoint a data protection officer, as I generally do not employ 20 or more persons involved in the automated processing of personal data (Section 38 (1) BDSG) and do not carry out any processing that would trigger the appointment requirement under Article 37 (1) GDPR. If you have any questions about data protection, please contact me using the details provided under "Controller" above.
3. Transfer to third parties
There are moments when I share your personal data with third parties – but only where it's genuinely necessary to operate my Website or provide my services. Every external service provider I work with has been carefully chosen and is bound in writing to process your personal data solely on my behalf. Where the law requires it, I've put a data processing agreement in place with them under Article 28 GDPR.
The categories of recipients I work with are:
- hosting providers,
- booking and scheduling tool providers,
- online form and questionnaire providers,
- email delivery providers,
- video hosting providers, and
- web analytics providers.
What I don't do: sell your personal data, or hand it over to advertising networks.
4. Transfer to third countries
Sometimes your personal data travels beyond the EU/EEA – most often to the United States. Where there's no adequacy decision for that country under Article 45 GDPR, I make sure appropriate safeguards are in place under Article 46 GDPR, typically the standard contractual clauses approved by the European Commission.
5. Blocking and deletion
Your personal data gets deleted or blocked as soon as the purpose behind processing it no longer applies. I'll keep hold of your data for longer where the law requires it – particularly for tax and accounting purposes. It's also blocked or deleted once a statutory retention period runs out, unless further storage is still needed to conclude or perform a contract.
6. Automated decision-making
I don't use any automated decision-making within the meaning of Article 22 GDPR, meaning no decision with legal effect on you, or a similarly significant effect, is ever made by a machine alone.
My career test does evaluate your answers automatically to produce your result and your work profile. That is a form of profiling under Article 4 (4) GDPR. It is described in full in section II.6 below.
II. My Processing Activities
Here's a closer look at the personal data I process, why I process it, and the legal basis behind each activity.
1. Processing of personal data during your visit to my Website
Every time you drop by my Website, the following personal data gets processed automatically:
- IP address of your requesting computer;
- browser type, browser version and language used;
- your operating system;
- date and time of access of your visit;
- name of your access provider;
- name of the specific page or file accessed, and the amount of data transferred (access status/http status code);
- website from which your system accesses my Website ("referrer URL").
The legal basis for this is my legitimate interest (Article 6 (1) (f) GDPR). I've weighed my interest in offering, running and securing this Website against your interest in keeping your personal data confidential – and mine tips the scale here. Without this processing, offering the Website – including keeping it running and secure – simply wouldn't be technically possible. And in that sense, the Website's security works in your favor too.
Your personal data sits temporarily in server log files for the purposes described above.
The log files are deleted after the end of the respective browser session, at the latest after seven (7) days. Personal data, which must be stored for further evidentiary purposes, is excluded from deletion until the respective incident has been finally clarified.
2. Processing of personal data when contacting me
When you reach out to me – by email, phone, or through my contact form – I process the personal data you share purely to handle, respond to, or otherwise take care of your inquiry.
The legal basis for this is mainly Article 6 (1) (b) GDPR. Where the correspondence isn't necessary for performing a contract with me or taking steps toward one, the legal basis shifts to Article 6 (1) (f) GDPR – it's simply my legitimate interest to stay in touch with you and keep that communication organized and documented.
Once your inquiry has been fully answered, your personal data gets deleted – unless I'm bound by legal or other retention obligations.
3. Processing of personal data when booking a Intro Call
Booking a Intro Call through the widget on my Website? I process the personal data you share during that booking – your name, email address, and anything else you choose to tell me – to schedule, confirm and run the appointment, and to deliver my coaching services to you.
The legal basis for this is Article 6 (1) (b) GDPR, since the processing is necessary to take steps toward a contract with me and, if an engagement follows, to perform that contract.
4. Processing of personal data when you subscribe to my newsletter
You can subscribe to my newsletter, "Monday Mood", through the form on my Website. I process the email address you enter, together with a first name if you choose to give one, for the sole purpose of sending you that newsletter.
Signing up uses a double opt-in procedure. After you enter your address, you receive one email asking you to confirm. Until you click the link in that email, nothing is sent to you and your address stays suppressed on the mailing list. When you confirm, I record the time of confirmation, the page you signed up from, your IP address and your browser's user agent, together with the version of the consent wording you were shown (currently v1-2026-08), so that I can demonstrate your consent as required by Article 7 (1) GDPR.
The legal basis for sending you the newsletter is your consent under Article 6 (1) (a) GDPR. The legal basis for keeping the record of that consent is my legal obligation and legitimate interest in being able to prove it, Article 6 (1) (c) and (f) GDPR.
You can withdraw your consent at any time, with the unsubscribe link at the foot of every issue or by emailing me at julius@revelionmethod.com. Withdrawal does not affect the lawfulness of any processing carried out before it. Your address is removed from the mailing list immediately on unsubscribe; the record of consent is kept only for as long as I may need it to demonstrate lawful processing, and is then deleted.
The newsletter does not contain tracking pixels, and I do not measure whether you open an issue or which links you click.
The list itself is stored in a Postgres database operated by Supabase, Inc. (970 Toa Payoh North, Singapore, with EU operations), which processes it on my behalf as a processor under Article 28 GDPR. The database is hosted in the European Union (Frankfurt). Where any support access involves a transfer outside the EU, I rely on the Standard Contractual Clauses approved by the EU Commission under Article 46 GDPR. Supabase's own handling of personal data is described in its privacy policy.
The newsletter is delivered by Resend (Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA), which processes your email address on my behalf as a processor under Article 28 GDPR. Because this involves a transfer to the USA, I rely on the Standard Contractual Clauses approved by the EU Commission as an appropriate safeguard under Article 46 GDPR. Resend's own handling of personal data is described in its privacy policy.
5. Processing of personal data in my preparation questionnaire
Once you've booked a Intro Call, I invite you to fill in a short preparation questionnaire. That questionnaire runs on Tally, a form tool from Tally BV, Belgium, and it opens on Tally's own website rather than on mine. Filling it in is entirely voluntary; you can come to the call without it.
What you write there – your answers, along with your name and email address – I process to prepare properly for our conversation and to tailor my coaching services to your situation. The legal basis for this is Article 6 (1) (b) GDPR, since the processing is necessary to take steps toward a contract with me and, if an engagement follows, to perform that contract.
Tally processes this data on my behalf as a processor under Article 28 GDPR and stores it on servers in Europe. Your answers get deleted once they're no longer needed for our work together, unless I'm bound by legal retention obligations. Tally's own handling of your personal data is described in its privacy policy.
6. Processing of personal data when you take my career test
My career test "Your Next Career Step" runs at test.revelion.coach. It asks you 35 short statements and five questions about your situation, and sends you a written result by email.
What I process.
- your answers to the statements and questions, including anything you write in the two optional free text fields;
- your email address, and, if you give them, your first name and your LinkedIn profile address;
- how you reached the test (for example "LinkedIn" or "website"), and, if you arrived through a personal link I sent you, a campaign code and your LinkedIn profile address contained in that link;
- a one-way encrypted (hashed) form of your browser's user agent and, if you tick the newsletter box, of your IP address, plus the country your connection comes from;
- the result computed from your answers: your scores, your result, your work profile and an internal score that helps me judge whether and how I could help you.
Why, and on which legal basis.
- To compute your result and send it to you, because you asked for it: Article 6 (1) (b) GDPR. Your answers are saved as you go, so that you do not lose them if you close the page.
- To tell me that someone took the test, and to prepare a possible conversation with you (including the internal score and suggested questions): my legitimate interest in offering my coaching services to people for whom they are relevant, Article 6 (1) (f) GDPR. This evaluation never leads to an automated decision about you. It only helps me prepare. You can object to it at any time.
- To send you the short email series about your result, my monthly newsletter and a reminder to retake the test after six months, only if you ticked the box and confirmed by email (double opt-in): your consent, Article 6 (1) (a) GDPR. I keep proof of that consent (time, hashed IP address) under Article 6 (1) (c) and (f) GDPR. You can withdraw it at any time with the unsubscribe link in every email.
A note on the free text fields. They are optional. Please do not write anything about your health there. If you do so anyway, I only use it to prepare our conversation and to show it back to you in your result, based on your explicit consent given by entering it (Article 9 (2) (a) GDPR), which you can withdraw at any time.
No cookies. The test sets no cookies. Your progress is kept in your own browser's local storage, only so that a reload does not lose your answers. This is strictly necessary for the service you asked for (Section 25 (2) No. 2 TDDDG). Visits are counted with Vercel Web Analytics, which works without cookies and without storing a personal identifier.
Who processes it on my behalf. The test is hosted by Vercel Inc., 440 N Barrington Ave #1181, Los Angeles, CA 90049, USA, on servers in Frankfurt. The data is stored in a Supabase database in Frankfurt (see section II.4 above). Emails are delivered by Resend (see section II.4 above). All three act as processors under Article 28 GDPR. For transfers to the USA I rely on the Standard Contractual Clauses under Article 46 GDPR.
How long I keep it. If you start the test but do not leave an email address, your answers are deleted automatically after 90 days. If you complete it, your answers, result and email address are deleted automatically three years after you took the test, unless you are still subscribed to my emails. You can ask me to delete everything earlier at any time, and I will do so completely.
7. Cookies and the tools that make my Website tick
a) The cookies that keep things running
My Website runs on a handful of functional cookies, simply because it needs them to work properly for you. Cookies are small text files that quietly note how you use a website; they sit on your device and stick around for your next visit. Nothing scary here: they cause no damage to your device and carry no viruses.
These cookies never get linked to your IP address, and I don't collect any other personal data through them. I simply use what they tell me to keep my Website running smoothly, to improve it over time, and to keep my IT security in good shape.
The legal basis for this is my legitimate interest (Article 6 (1) (f) GDPR) and Section 25 (2) No. 2 TDDDG. I've weighed my interest in offering these cookie-powered features against your interest in keeping your data private – and mine wins out here, simply because the Website wouldn't work properly without them.
Prefer no cookies at all? You can browse my Website that way too, just switch off cookie storage in your browser settings – though a few features might not work as smoothly. Session cookies disappear automatically the moment you close your browser, unless you've told your browser to handle them differently. You'll find the full list of cookies, and the option to change your choice, in my Cookie Policy.
b) Calendly – my booking sidekick
To make booking a Intro Call with me as easy as possible, I rely on Calendly, a scheduling tool from Calendly, LLC. The Calendly widget pops up the moment you step into the booking area of my Website, and it's technically necessary to deliver the booking function you've specifically asked for. Calendly may drop its own technically necessary cookies along the way.
The legal basis here is Section 25 (2) No. 2 TDDDG and Article 6 (1) (b) GDPR, since loading the widget is strictly necessary to give you the booking function you asked for. Calendly handles your personal data under its own privacy policy, available on Calendly's website.
c) Fonts – for a Website that looks the part
My Website uses the typefaces Jost, Inter and Geist Mono. These font files sit on my own server and are delivered together with the rest of the Website. No connection to Google servers is made when they load, and no data about your visit is passed to Google for this purpose.
d) jsDelivr / Wix Video CDN – behind-the-scenes delivery
Some of the smoother touches on my Website – like certain script libraries (e.g., GSAP, Lenis) and the testimonial videos – are delivered via jsDelivr and the Wix Video content delivery network. Loading this content triggers technical requests to these respective content delivery networks.
The legal basis for this is my legitimate interest in delivering my Website's content reliably and efficiently (Article 6 (1) (f) GDPR).
e) Google Analytics 4 – so I know what's working
I use Google Analytics 4 on my Website, a web analytics service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), to understand what's resonating with visitors. It only springs into action once you've given the green light via my cookie banner.
Google Analytics 4 uses cookies that stick around for up to 14 months. The information these cookies pick up about your Website use travels to and is stored on Google's servers, including in the United States. Google shortens (anonymizes) your IP address before any geographic analysis happens. On my behalf, Google turns this data into insights about how the Website is used, compiles activity reports, and provides me with other services tied to Website and internet usage.
The legal basis for this is your consent (Article 6 (1) (a) GDPR, Section 25 (1) TDDDG). You're always free to withdraw it, with effect for the future, via my cookie settings. Where your data heads to the United States, I lean on the standard contractual clauses approved by the European Commission as an appropriate safeguard under Article 46 GDPR (see also "Transfer to third countries" above).
f) Social media – just a click away, nothing more
You won't find any social media cookies quietly embedded in my Website (no plug-ins here). Any buttons you spot simply link out to the respective social media service's own website – their presence alone doesn't trigger any data collection or transfer. Only once you actually click a button will you be taken to that provider's page. This Privacy Policy covers my Website only, not any other websites I link to. Those providers handle your data under their own privacy policies.
8. Retention periods
I hold on to the personal data described above only for as long as it's genuinely needed for the purposes set out in this Privacy Policy, or as long as the law requires – particularly commercial and tax retention obligations under German law. Once those purposes fall away and no statutory retention duty remains, your personal data gets deleted or anonymized.
9. Security
I implement technical and organizational measures ("TOMs") to protect your data against loss, manipulation or unauthorized access. My Website is transmitted in encrypted form via HTTPS. Even with all reasonable precautions, no data transmission over the internet can ever be guaranteed 100% secure – so please think twice before emailing me particularly sensitive personal data.
III. Data Subject Rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- right of access (Article 15 GDPR);
- right to rectification (Article 16 GDPR);
- right to erasure ("right to be forgotten") (Article 17 GDPR);
- right to restriction of processing (Article 18 GDPR);
- right to data portability (Article 20 GDPR);
- right to object to the processing (Article 21 GDPR);
- right to withdraw consent at any time with effect for the future.
Where I process your personal data based on my legitimate interests (Article 6 (1) (f) GDPR), you're welcome to object – just get in touch with me (see "Controller" for contact details). The same goes if I'm relying on your consent: you can withdraw it at any time, with effect for the future.
You are also entitled to lodge a complaint with a supervisory authority regarding the processing of your personal data, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
IV. Minors
My services are built for adults and aren't intended for anyone under 18. I don't knowingly collect personal data from children.
V. Updates to this Privacy Policy
I may update this Privacy Policy from time to time, whenever legal requirements change or my services evolve. Whatever version is current, along with its date, is always available right here on this page.
This information does not constitute legal advice. Requirements may vary depending on the applicable jurisdiction. If in doubt, please consult qualified legal counsel.